Sale Gate privacy

Privacy Policy

How Sale Gate handles account, business, device and customer information when providing the service.

Last updated: September 25, 2026

1. Who is responsible

[Company legal name] operates Sale Gate. For account, support, security and billing information we collect for our own purposes, we are the organisation or information controller responsible for that data.

A merchant usually decides why and how its customers' and staff data is used. For that data, the merchant is normally the organisation or information controller and Sale Gate acts as its data intermediary, processor or service provider. Contact the merchant first for an order or loyalty request.

2. Information we collect

The information depends on the features used and may include:

  • Account and business details such as names, email addresses, phone numbers, company details, roles and consent records.
  • Commerce data such as products, orders, payments, receipts, stock, staff activity, customers, loyalty balances and delivery details.
  • Device and technical data such as device identifiers, IP address, app version, browser, request logs and security events.
  • Support communications and files you choose to provide.
  • Payment references and status from payment providers; Sale Gate should not store full card credentials.

3. Why we use information

We use information only for reasonable, notified purposes, including to:

  • Provide, authenticate, operate and support Sale Gate.
  • Process orders, receipts, loyalty, payments and merchant-requested communications.
  • Secure accounts, prevent abuse, troubleshoot incidents and maintain audit records.
  • Meet tax, accounting, legal and regulatory duties.
  • Measure and improve reliability and features using appropriately limited data.
  • Send marketing only where valid consent or another lawful basis exists, with an opt-out.

4. Consent and other legal grounds

Where consent is required, we or the merchant explain the purpose and provide a genuine choice. Marketing consent is separate from completing an order and may be withdrawn with reasonable notice.

Depending on the country and context, processing may also be necessary to perform a contract, comply with law, protect vital interests or pursue a legitimate business purpose allowed by law. We do not make unnecessary personal-data consent a condition of service.

5. Who receives information

We do not sell personal information. We disclose it only where needed for the stated purposes, under suitable confidentiality and data-protection terms.

Recipients may include:

  • The merchant and staff authorised for its account.
  • Hosting, backup, email, SMS, monitoring, support and payment service providers.
  • Professional advisers, auditors, insurers or a successor in a properly managed business transaction.
  • Courts, regulators, law enforcement or other parties when legally required or necessary to protect rights and safety.

6. International transfers

The configured hosting and backup location is [Hosting country / cloud region]. Service providers or support personnel may process data in other countries.

Before transferring protected data overseas, we use contracts and other safeguards intended to provide protection comparable to applicable requirements, including Singapore's transfer limitation rules and Mongolia's requirements. The final deployment locations and safeguards must be confirmed before launch.

7. Retention

We keep information only as long as needed for the service, security, disputes, backups and legal, tax or accounting duties. Retention varies by record type, merchant instructions and law.

When information is no longer required, we delete, anonymise or securely dispose of it. Backup copies may remain for a limited rotation period and are protected from ordinary use. The final retention schedule must be documented before launch.

8. Security

We use reasonable administrative, technical and physical measures designed to prevent unauthorised access, collection, use, disclosure, alteration or loss. These include access controls, encryption where appropriate, tenant separation, logging, backups and incident procedures.

No system is completely secure. Merchants must also protect their devices, accounts, networks, exports and staff access and notify us promptly of suspected compromise.

9. Your choices and rights

Subject to applicable law and exceptions, you may ask to:

  • Know what personal information is held and how it has been used or disclosed.
  • Access a copy and correct inaccurate or incomplete information.
  • Withdraw consent, including marketing consent, and learn the likely consequences.
  • Request deletion, restriction, objection or portability where the law provides it.
  • Complain to us, the merchant or the relevant supervisory authority.

10. Cookies and local storage

Sale Gate currently uses only essential or preference technologies: a language cookie, a secure sign-in session cookie, a back-office sidebar preference, and local browser storage for device sessions, carts and offline operation.

These are needed to sign in, remember a choice, keep an order cart or provide offline and security functions. We do not currently set advertising cookies, so no marketing-cookie banner is shown.

Optional error monitoring is configured to avoid collecting cookies, request bodies, headers and user identity. If non-essential analytics or advertising cookies are introduced, this policy and the consent interface must be updated before they are enabled.

11. Data incidents

We assess suspected personal-data incidents, contain and investigate them, and notify affected merchants, individuals and authorities when required. A data intermediary will notify the responsible merchant without undue delay when applicable.

12. Children

Sale Gate business accounts are not intended for children. Merchants must assess age and guardian-consent requirements for any customer ordering or loyalty programme they offer to minors.

13. Policy changes

We may update this Policy as the service or law changes. We will publish the new date and provide appropriate notice for material changes, and seek fresh consent where required.

14. Contact and complaints

For Sale Gate privacy questions or rights requests, contact [privacy@your-domain]. We may need to verify identity and clarify the request. For merchant-controlled customer data, we may refer the request to that merchant.

You may also complain to the competent authority, including Singapore's Personal Data Protection Commission or Mongolia's National Human Rights Commission, subject to its jurisdiction. General contact: [support@your-domain]; registered address: [Registered office address].